Penetration testing
Penetration testing that proves real risk
A controlled, authorised simulation of a genuine attack — manually chaining weaknesses to show real impact, and exactly how to stop it.
Test types
Where we test
Web application
Auth, authorisation, business logic and injection across roles.
API testing
REST and GraphQL access control and data exposure.
Network & infrastructure
External and internal services, segmentation, escalation paths.
Cloud configuration
Identity, storage, network and workload misconfigurations.
Social engineering
Consent-based phishing that measures human resilience.
Mobile & thick client
Mobile apps and back ends: storage, transport, API misuse.
Methodology
How we run a test
Aligned with recognised industry methodology and the OWASP Testing Guide.
Rules of engagement
Scope and escalation contacts authorised in writing first.
Mapping
Attack surface, users and tech mapped without impacting uptime.
Analysis
Manual testing finds what a scanner alone would miss.
Safe exploitation
Impact confirmed with the least intrusive proof possible.
Reporting
Prioritised findings with evidence and business impact.
Verification
Fixes retested and an updated status issued.
Severity model
How we rate findings
Likelihood and business impact, aligned with CVSS.
| Severity | Meaning | Response |
|---|---|---|
| Critical | Direct, high-impact compromise. | Fix immediately. |
| High | Serious, realistically exploitable. | Fix this cycle. |
| Medium | Meaningful, often conditional risk. | Plan a fix soon. |
| Low | Limited impact or hardening. | Address as maintenance. |
Rules of engagement
Safe, legal, and in scope
Every test is bounded by a signed agreement. We only ever test assets you are authorised to have tested.
- Written authorisation and defined scope
- Production-safe techniques
- No data exfiltration beyond proof
- Findings shared securely
- Immediate contact on anything high-risk
Next step
Ready to test your application?
Send the target and your goals; we propose scope, timeline and a fixed price.